Microsoft Defender XDR
General

Playbook Responding Ransomware M365 Defender

In brief

The playbook now refers to Microsoft Defender instead of Microsoft Defender XDR when describing consolidated visibility into impacted or at-risk assets, and updates the linked article title accordingly.

What Defender admins need to know

No administrator action is required. Use the updated Microsoft Defender terminology when following the playbook.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Step 1: Assess the scope of the incident

Run through this list of questions and tasks to discover the extent of the attack. Microsoft Defender XDR can provide a consolidated view of all impacted or at-risk assets to aid in your incident response assessment. See Incident response with Microsoft Defender. You can use the alerts and the evidence list in the incident to determine:

  • Which user accounts might be compromised?
    • Which accounts were used to deliver the payload?